Executive brief
A vulnerability was identified in the Linux kernel's scheduler extension (sched_ext) that could lead to a system crash. The issue occurs during a specific initialization failure where the system attempts to access task information after it has already been released from memory. This could potentially be exploited by a local attacker to cause a denial-of-service condition.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel within the `scx_root_enable_workfn()` function (and related enable work functions) of the `sched_ext` scheduler class. The root cause is an incorrect ordering of operations where `put_task_struct(p)` is called before `scx_error()` dereferences `p->comm` and `p->pid`. If the call to `put_task_struct` drops the final reference, the task structure is freed synchronously, leading to a UAF when the error logging function attempts to access the task's metadata. This issue is triggered during initialization failure paths. Patches have been released for various stable branches including 6.12.y and newer.
Affected products
- Linux Linux 6.12+
Timeline
- 2026-05-11: disclosed: Initial fix authored by Tejun Heo
- 2026-07-24: advisory: CVE published in NVD dataset